Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To reduce the risk of an external data breach, protect the accounts and systems an attacker could use, limit access to sensitive information, close avoidable exposure, and prepare to detect and recover from an incident. No single control can guarantee that an organization will avoid a breach. The practical goal is to make unauthorized access harder, limit what an attacker can reach, and preserve the ability to respond.

Start with the information and systems you need to protect

Security work is easier to prioritize when you know what information matters, where it is stored, and which accounts and systems can reach it. NIST’s final Data Confidentiality: Identifying and Protecting Assets Against Data Breaches (SP 1800-28, February 23, 2024) focuses on identifying and protecting assets against attacks on data confidentiality.

  1. Identify sensitive data. List the information whose disclosure would harm customers, employees, or the organization, and note where it is stored or transmitted.
  2. Map access. Identify the user accounts, devices, applications, and outside providers that can access that information.
  3. Prioritize exposed and consequential assets. Give attention first to systems reachable from the internet and accounts that can reach critical systems or sensitive data.
  4. Assign responsibility. Make clear who owns each important system and who is responsible for keeping its access and protections current.

This inventory is not paperwork for its own sake: it helps you focus controls on the information and access paths that matter most.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make account takeover harder

Stolen credentials can give an outside actor a route into email, remote access, and other systems. The joint CISA, MS-ISAC, NSA, and FBI #StopRansomware Guide recommends phishing-resistant multifactor authentication (MFA) and least privilege.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Prioritize high-impact accounts

Enable phishing-resistant MFA first for email, VPN or other remote-access services, and accounts that can reach critical systems. MFA adds a verification step beyond a password; phishing-resistant methods are intended to better withstand attempts to trick users into handing over credentials.

Limit permissions

Give each person and service account only the access needed for its work. Review who can access sensitive information and critical systems, and remove access when it is no longer required. This limits the potential reach of an account that is compromised.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Reduce internet-facing exposure

Keep an up-to-date view of systems exposed to the internet, then address vulnerabilities and misconfigurations that could make them easier to exploit. CISA’s guidance on ransomware-caused data breaches calls attention to internet-facing vulnerabilities and misconfigurations; the same exposure-management work is relevant to reducing broader external attack paths.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Track internet-facing systems and the people responsible for them.
  • Prioritize fixing known vulnerabilities and correcting unsafe configurations on exposed systems.
  • Include cloud services and remote-access systems in the review, not just equipment in an office.
  • Revisit the inventory when systems, providers, or access arrangements change.

Treat supplier access as part of your security boundary

A third-party provider or managed service provider with access to your systems can become part of your organization’s risk surface. The joint #StopRansomware Guide recommends attention to third-party access. Limit each provider’s permissions to what it needs, and set security requirements formally rather than relying on informal assumptions.

Rank #3
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Review which provider accounts remain active, what systems they can reach, and who inside your organization approves that access. Where a provider no longer needs access, remove it.

Use backups to recover—not as a substitute for breach prevention

Backups can help restore information after ransomware or another destructive event, but they do not prevent an attacker from accessing or copying data before the incident is discovered. CISA recommends keeping backups encrypted and offline, and testing restoration regularly. For a physical external drive, disconnect it when it is not actively backing up; a connected drive may also be reached by ransomware.

Rank #4
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

Choose a backup arrangement you can restore from

CISA describes both a secure external hard drive and a properly vetted cloud service as backup options. The choice is less important than whether the copy is protected from compromise and deletion, and whether you can restore it when needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Backup option Isolation and access Encryption and recovery
External hard drive CISA advises storing it safely and disconnecting it when it is not actively backing up. CISA recommends encrypted backups and regular restoration tests; it does not establish a particular drive model or capacity.
Vetted cloud backup CISA identifies a properly vetted cloud service as an option. The source guidance does not establish one provider or a universal access configuration. CISA recommends encrypted backups and regular restoration tests. Cloud-specific protections such as logging, alerts, delete protection, and versioning may be available, depending on the service.

Verify the recovery path

  • Keep backup copies encrypted and isolated from routine access where possible.
  • Test restoration regularly so you know the copy is usable and understand the recovery steps.
  • For cloud backups, use available logging and alerts, and consider delete protection and versioning where supported.
  • For a physical drive, disconnect it outside active backup periods and store it securely.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prepare to detect, respond, and recover

Prevention cannot eliminate risk, so preparation matters. NIST SP 1800-29, Data Confidentiality: Detect, Respond to, and Recover from Data Breaches, was published in final form on February 23, 2024. The joint #StopRansomware Guide also recommends maintaining and exercising an incident-response plan.

  1. Decide how an incident will be reported. Staff should know where to raise a suspected compromise or unexpected exposure.
  2. Assign response roles. Identify who coordinates technical investigation, business decisions, communications, and recovery.
  3. Plan how to contain access. Include ways to disable or restrict compromised accounts and isolate affected systems.
  4. Exercise the plan. Walk through a realistic scenario, identify gaps in responsibilities or recovery, and update the plan based on what the exercise reveals.
  5. Include recovery. Know how to restore from protected backups and how to determine whether systems are ready to return to service.

Use current guidance to structure ransomware improvements

External data breaches are not limited to ransomware, but ransomware guidance offers practical controls for reducing exposure and improving resilience. On June 11, 2026, NIST announced the final version of Interagency Report 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework (CSF) 2.0 Community Profile. NIST says it translates the CSF 2.0 into practical ransomware prevention and mitigation actions and can help organizations assess readiness and prioritize improvements.

NIST SP 1800-25 also addresses protection against ransomware and other destructive events, including backups, secure storage, integrity checking, audit logs, and vulnerability management. Use these references to inform a broader security program, while keeping the distinction clear: resilience against ransomware supports recovery, but reducing external breach risk also requires protecting access and sensitive data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.